f858cd95ecbacec81334cad5c85e11ec6537e724
[strongswan.git] / src / libfreeswan / pfkey.h
1 /*
2 * FreeS/WAN specific PF_KEY headers
3 * Copyright (C) 1999, 2000, 2001 Richard Guy Briggs.
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 *
15 * RCSID $Id: pfkey.h,v 1.2 2004/03/22 21:53:18 as Exp $
16 */
17
18 #ifndef __NET_IPSEC_PF_KEY_H
19 #define __NET_IPSEC_PF_KEY_H
20 #ifdef __KERNEL__
21 extern struct proto_ops pfkey_proto_ops;
22 typedef struct sock pfkey_sock;
23 extern int debug_pfkey;
24
25 extern /* void */ int pfkey_init(void);
26 extern /* void */ int pfkey_cleanup(void);
27
28 extern struct sock *pfkey_sock_list;
29 struct socket_list
30 {
31 struct socket *socketp;
32 struct socket_list *next;
33 };
34 extern int pfkey_list_insert_socket(struct socket*, struct socket_list**);
35 extern int pfkey_list_remove_socket(struct socket*, struct socket_list**);
36 extern struct socket_list *pfkey_open_sockets;
37 extern struct socket_list *pfkey_registered_sockets[SADB_SATYPE_MAX+1];
38
39 /*
40 * There is a field-by-field copy in klips/net/ipsec/ipsec_alg.h
41 * please keep in sync until we migrate all support stuff
42 * to ipsec_alg objects
43 */
44 struct supported
45 {
46 uint16_t supported_alg_exttype;
47 uint8_t supported_alg_id;
48 uint8_t supported_alg_ivlen;
49 uint16_t supported_alg_minbits;
50 uint16_t supported_alg_maxbits;
51 };
52 extern struct supported_list *pfkey_supported_list[SADB_SATYPE_MAX+1];
53 struct supported_list
54 {
55 struct supported *supportedp;
56 struct supported_list *next;
57 };
58 extern int pfkey_list_insert_supported(struct supported*, struct supported_list**);
59 extern int pfkey_list_remove_supported(struct supported*, struct supported_list**);
60
61 struct sockaddr_key
62 {
63 uint16_t key_family; /* PF_KEY */
64 uint16_t key_pad; /* not used */
65 uint32_t key_pid; /* process ID */
66 };
67
68 struct pfkey_extracted_data
69 {
70 struct ipsec_sa* ips;
71 struct ipsec_sa* ips2;
72 struct eroute *eroute;
73 };
74
75 extern int
76 pfkey_alloc_eroute(struct eroute** eroute);
77
78 extern int
79 pfkey_sa_process(struct sadb_ext *pfkey_ext,
80 struct pfkey_extracted_data* extr);
81
82 extern int
83 pfkey_lifetime_process(struct sadb_ext *pfkey_ext,
84 struct pfkey_extracted_data* extr);
85
86 extern int
87 pfkey_address_process(struct sadb_ext *pfkey_ext,
88 struct pfkey_extracted_data* extr);
89
90 extern int
91 pfkey_key_process(struct sadb_ext *pfkey_ext,
92 struct pfkey_extracted_data* extr);
93
94 extern int
95 pfkey_ident_process(struct sadb_ext *pfkey_ext,
96 struct pfkey_extracted_data* extr);
97
98 extern int
99 pfkey_sens_process(struct sadb_ext *pfkey_ext,
100 struct pfkey_extracted_data* extr);
101
102 extern int
103 pfkey_prop_process(struct sadb_ext *pfkey_ext,
104 struct pfkey_extracted_data* extr);
105
106 extern int
107 pfkey_supported_process(struct sadb_ext *pfkey_ext,
108 struct pfkey_extracted_data* extr);
109
110 extern int
111 pfkey_spirange_process(struct sadb_ext *pfkey_ext,
112 struct pfkey_extracted_data* extr);
113
114 extern int
115 pfkey_x_kmprivate_process(struct sadb_ext *pfkey_ext,
116 struct pfkey_extracted_data* extr);
117
118 extern int
119 pfkey_x_satype_process(struct sadb_ext *pfkey_ext,
120 struct pfkey_extracted_data* extr);
121
122 extern int
123 pfkey_x_debug_process(struct sadb_ext *pfkey_ext,
124 struct pfkey_extracted_data* extr);
125
126 extern int pfkey_register_reply(int satype, struct sadb_msg *);
127 extern int pfkey_upmsg(struct socket *, struct sadb_msg *);
128 extern int pfkey_expire(struct ipsec_sa *, int);
129 extern int pfkey_acquire(struct ipsec_sa *);
130 #else /* ! __KERNEL__ */
131
132 extern void (*pfkey_debug_func)(const char *message, ...);
133
134 #endif /* __KERNEL__ */
135
136 extern uint8_t satype2proto(uint8_t satype);
137 extern uint8_t proto2satype(uint8_t proto);
138 extern char* satype2name(uint8_t satype);
139 extern char* proto2name(uint8_t proto);
140
141 struct key_opt
142 {
143 uint32_t key_pid; /* process ID */
144 struct sock *sk;
145 };
146
147 #define key_pid(sk) ((struct key_opt*)&((sk)->protinfo))->key_pid
148
149 #define IPSEC_PFKEYv2_ALIGN (sizeof(uint64_t)/sizeof(uint8_t))
150 #define BITS_PER_OCTET 8
151 #define OCTETBITS 8
152 #define PFKEYBITS 64
153 #define DIVUP(x,y) ((x + y -1) / y) /* divide, rounding upwards */
154 #define ALIGN_N(x,y) (DIVUP(x,y) * y) /* align on y boundary */
155
156 #define PFKEYv2_MAX_MSGSIZE 4096
157
158 /*
159 * PF_KEYv2 permitted and required extensions in and out bitmaps
160 */
161 struct pf_key_ext_parsers_def {
162 int (*parser)(struct sadb_ext*);
163 char *parser_name;
164 };
165
166
167 extern unsigned int extensions_bitmaps[2/*in/out*/][2/*perm/req*/][SADB_MAX + 1/*ext*/];
168 #define EXT_BITS_IN 0
169 #define EXT_BITS_OUT 1
170 #define EXT_BITS_PERM 0
171 #define EXT_BITS_REQ 1
172
173 extern void pfkey_extensions_init(struct sadb_ext *extensions[SADB_EXT_MAX + 1]);
174 extern void pfkey_extensions_free(struct sadb_ext *extensions[SADB_EXT_MAX + 1]);
175 extern void pfkey_msg_free(struct sadb_msg **pfkey_msg);
176
177 extern int pfkey_msg_parse(struct sadb_msg *pfkey_msg,
178 struct pf_key_ext_parsers_def *ext_parsers[],
179 struct sadb_ext **extensions,
180 int dir);
181
182 /*
183 * PF_KEYv2 build function prototypes
184 */
185
186 int
187 pfkey_msg_hdr_build(struct sadb_ext** pfkey_ext,
188 uint8_t msg_type,
189 uint8_t satype,
190 uint8_t msg_errno,
191 uint32_t seq,
192 uint32_t pid);
193
194 int
195 pfkey_sa_ref_build(struct sadb_ext ** pfkey_ext,
196 uint16_t exttype,
197 uint32_t spi, /* in network order */
198 uint8_t replay_window,
199 uint8_t sa_state,
200 uint8_t auth,
201 uint8_t encrypt,
202 uint32_t flags,
203 uint32_t/*IPsecSAref_t*/ ref);
204
205 int
206 pfkey_sa_build(struct sadb_ext ** pfkey_ext,
207 uint16_t exttype,
208 uint32_t spi, /* in network order */
209 uint8_t replay_window,
210 uint8_t sa_state,
211 uint8_t auth,
212 uint8_t encrypt,
213 uint32_t flags);
214
215 int
216 pfkey_lifetime_build(struct sadb_ext ** pfkey_ext,
217 uint16_t exttype,
218 uint32_t allocations,
219 uint64_t bytes,
220 uint64_t addtime,
221 uint64_t usetime,
222 uint32_t packets);
223
224 int
225 pfkey_address_build(struct sadb_ext** pfkey_ext,
226 uint16_t exttype,
227 uint8_t proto,
228 uint8_t prefixlen,
229 struct sockaddr* address);
230
231 int
232 pfkey_key_build(struct sadb_ext** pfkey_ext,
233 uint16_t exttype,
234 uint16_t key_bits,
235 char* key);
236
237 int
238 pfkey_ident_build(struct sadb_ext** pfkey_ext,
239 uint16_t exttype,
240 uint16_t ident_type,
241 uint64_t ident_id,
242 uint8_t ident_len,
243 char* ident_string);
244
245 #ifdef NAT_TRAVERSAL
246 #ifdef __KERNEL__
247 extern int pfkey_nat_t_new_mapping(struct ipsec_sa *, struct sockaddr *, __u16);
248 extern int pfkey_x_nat_t_type_process(struct sadb_ext *pfkey_ext, struct pfkey_extracted_data* extr);
249 extern int pfkey_x_nat_t_port_process(struct sadb_ext *pfkey_ext, struct pfkey_extracted_data* extr);
250 #endif /* __KERNEL__ */
251 int
252 pfkey_x_nat_t_type_build(struct sadb_ext** pfkey_ext,
253 uint8_t type);
254 int
255 pfkey_x_nat_t_port_build(struct sadb_ext** pfkey_ext,
256 uint16_t exttype,
257 uint16_t port);
258 #endif
259
260 int
261 pfkey_sens_build(struct sadb_ext** pfkey_ext,
262 uint32_t dpd,
263 uint8_t sens_level,
264 uint8_t sens_len,
265 uint64_t* sens_bitmap,
266 uint8_t integ_level,
267 uint8_t integ_len,
268 uint64_t* integ_bitmap);
269
270 int pfkey_x_protocol_build(struct sadb_ext **, uint8_t);
271
272
273 int
274 pfkey_prop_build(struct sadb_ext** pfkey_ext,
275 uint8_t replay,
276 unsigned int comb_num,
277 struct sadb_comb* comb);
278
279 int
280 pfkey_supported_build(struct sadb_ext** pfkey_ext,
281 uint16_t exttype,
282 unsigned int alg_num,
283 struct sadb_alg* alg);
284
285 int
286 pfkey_spirange_build(struct sadb_ext** pfkey_ext,
287 uint16_t exttype,
288 uint32_t min,
289 uint32_t max);
290
291 int
292 pfkey_x_kmprivate_build(struct sadb_ext** pfkey_ext);
293
294 int
295 pfkey_x_satype_build(struct sadb_ext** pfkey_ext,
296 uint8_t satype);
297
298 int
299 pfkey_x_debug_build(struct sadb_ext** pfkey_ext,
300 uint32_t tunnel,
301 uint32_t netlink,
302 uint32_t xform,
303 uint32_t eroute,
304 uint32_t spi,
305 uint32_t radij,
306 uint32_t esp,
307 uint32_t ah,
308 uint32_t rcv,
309 uint32_t pfkey,
310 uint32_t ipcomp,
311 uint32_t verbose);
312
313 int
314 pfkey_msg_build(struct sadb_msg** pfkey_msg,
315 struct sadb_ext* extensions[],
316 int dir);
317
318 /* in pfkey_v2_debug.c - routines to decode numbers -> strings */
319 const char *
320 pfkey_v2_sadb_ext_string(int extnum);
321
322 const char *
323 pfkey_v2_sadb_type_string(int sadb_type);
324
325
326 #endif /* __NET_IPSEC_PF_KEY_H */
327
328 /*
329 * $Log: pfkey.h,v $
330 * Revision 1.2 2004/03/22 21:53:18 as
331 * merged alg-0.8.1 branch with HEAD
332 *
333 * Revision 1.1.2.1.2.1 2004/03/16 09:48:18 as
334 * alg-0.8.1rc12 patch merged
335 *
336 * Revision 1.1.2.1 2004/03/15 22:30:06 as
337 * nat-0.6c patch merged
338 *
339 * Revision 1.1 2004/03/15 20:35:25 as
340 * added files from freeswan-2.04-x509-1.5.3
341 *
342 * Revision 1.42 2003/08/25 22:08:19 mcr
343 * removed pfkey_proto_init() from pfkey.h for 2.6 support.
344 *
345 * Revision 1.41 2003/05/07 17:28:57 mcr
346 * new function pfkey_debug_func added for us in debugging from
347 * pfkey library.
348 *
349 * Revision 1.40 2003/01/30 02:31:34 rgb
350 *
351 * Convert IPsecSAref_t from signed to unsigned to fix apparent SAref exhaustion bug.
352 *
353 * Revision 1.39 2002/09/20 15:40:21 rgb
354 * Switch from pfkey_alloc_ipsec_sa() to ipsec_sa_alloc().
355 * Added ref parameter to pfkey_sa_build().
356 * Cleaned out unused cruft.
357 *
358 * Revision 1.38 2002/05/14 02:37:24 rgb
359 * Change all references to tdb, TDB or Tunnel Descriptor Block to ips,
360 * ipsec_sa or ipsec_sa.
361 * Added function prototypes for the functions moved to
362 * pfkey_v2_ext_process.c.
363 *
364 * Revision 1.37 2002/04/24 07:36:49 mcr
365 * Moved from ./lib/pfkey.h,v
366 *
367 * Revision 1.36 2002/01/20 20:34:49 mcr
368 * added pfkey_v2_sadb_type_string to decode sadb_type to string.
369 *
370 * Revision 1.35 2001/11/27 05:27:47 mcr
371 * pfkey parses are now maintained by a structure
372 * that includes their name for debug purposes.
373 *
374 * Revision 1.34 2001/11/26 09:23:53 rgb
375 * Merge MCR's ipsec_sa, eroute, proc and struct lifetime changes.
376 *
377 * Revision 1.33 2001/11/06 19:47:47 rgb
378 * Added packet parameter to lifetime and comb structures.
379 *
380 * Revision 1.32 2001/09/08 21:13:34 rgb
381 * Added pfkey ident extension support for ISAKMPd. (NetCelo)
382 *
383 * Revision 1.31 2001/06/14 19:35:16 rgb
384 * Update copyright date.
385 *
386 * Revision 1.30 2001/02/27 07:04:52 rgb
387 * Added satype2name prototype.
388 *
389 * Revision 1.29 2001/02/26 19:59:33 rgb
390 * Ditch unused sadb_satype2proto[], replaced by satype2proto().
391 *
392 * Revision 1.28 2000/10/10 20:10:19 rgb
393 * Added support for debug_ipcomp and debug_verbose to klipsdebug.
394 *
395 * Revision 1.27 2000/09/21 04:20:45 rgb
396 * Fixed array size off-by-one error. (Thanks Svenning!)
397 *
398 * Revision 1.26 2000/09/12 03:26:05 rgb
399 * Added pfkey_acquire prototype.
400 *
401 * Revision 1.25 2000/09/08 19:21:28 rgb
402 * Fix pfkey_prop_build() parameter to be only single indirection.
403 *
404 * Revision 1.24 2000/09/01 18:46:42 rgb
405 * Added a supported algorithms array lists, one per satype and registered
406 * existing algorithms.
407 * Fixed pfkey_list_{insert,remove}_{socket,support}() to allow change to
408 * list.
409 *
410 * Revision 1.23 2000/08/27 01:55:26 rgb
411 * Define OCTETBITS and PFKEYBITS to avoid using 'magic' numbers in code.
412 *
413 * Revision 1.22 2000/08/20 21:39:23 rgb
414 * Added kernel prototypes for kernel funcitions pfkey_upmsg() and
415 * pfkey_expire().
416 *
417 * Revision 1.21 2000/08/15 17:29:23 rgb
418 * Fixes from SZI to untested pfkey_prop_build().
419 *
420 * Revision 1.20 2000/05/10 20:14:19 rgb
421 * Fleshed out sensitivity, proposal and supported extensions.
422 *
423 * Revision 1.19 2000/03/16 14:07:23 rgb
424 * Renamed ALIGN macro to avoid fighting with others in kernel.
425 *
426 * Revision 1.18 2000/01/22 23:24:06 rgb
427 * Added prototypes for proto2satype(), satype2proto() and proto2name().
428 *
429 * Revision 1.17 2000/01/21 06:26:59 rgb
430 * Converted from double tdb arguments to one structure (extr)
431 * containing pointers to all temporary information structures.
432 * Added klipsdebug switching capability.
433 * Dropped unused argument to pfkey_x_satype_build().
434 *
435 * Revision 1.16 1999/12/29 21:17:41 rgb
436 * Changed pfkey_msg_build() I/F to include a struct sadb_msg**
437 * parameter for cleaner manipulation of extensions[] and to guard
438 * against potential memory leaks.
439 * Changed the I/F to pfkey_msg_free() for the same reason.
440 *
441 * Revision 1.15 1999/12/09 23:12:54 rgb
442 * Added macro for BITS_PER_OCTET.
443 * Added argument to pfkey_sa_build() to do eroutes.
444 *
445 * Revision 1.14 1999/12/08 20:33:25 rgb
446 * Changed sa_family_t to uint16_t for 2.0.xx compatibility.
447 *
448 * Revision 1.13 1999/12/07 19:53:40 rgb
449 * Removed unused first argument from extension parsers.
450 * Changed __u* types to uint* to avoid use of asm/types.h and
451 * sys/types.h in userspace code.
452 * Added function prototypes for pfkey message and extensions
453 * initialisation and cleanup.
454 *
455 * Revision 1.12 1999/12/01 22:19:38 rgb
456 * Change pfkey_sa_build to accept an SPI in network byte order.
457 *
458 * Revision 1.11 1999/11/27 11:55:26 rgb
459 * Added extern sadb_satype2proto to enable moving protocol lookup table
460 * to lib/pfkey_v2_parse.c.
461 * Delete unused, moved typedefs.
462 * Add argument to pfkey_msg_parse() for direction.
463 * Consolidated the 4 1-d extension bitmap arrays into one 4-d array.
464 *
465 * Revision 1.10 1999/11/23 22:29:21 rgb
466 * This file has been moved in the distribution from klips/net/ipsec to
467 * lib.
468 * Add macros for dealing with alignment and rounding up more opaquely.
469 * The uint<n>_t type defines have been moved to freeswan.h to avoid
470 * chicken-and-egg problems.
471 * Add macros for dealing with alignment and rounding up more opaque.
472 * Added prototypes for using extention header bitmaps.
473 * Added prototypes of all the build functions.
474 *
475 * Revision 1.9 1999/11/20 21:59:48 rgb
476 * Moved socketlist type declarations and prototypes for shared use.
477 * Slightly modified scope of sockaddr_key declaration.
478 *
479 * Revision 1.8 1999/11/17 14:34:25 rgb
480 * Protect sa_family_t from being used in userspace with GLIBC<2.
481 *
482 * Revision 1.7 1999/10/27 19:40:35 rgb
483 * Add a maximum PFKEY packet size macro.
484 *
485 * Revision 1.6 1999/10/26 16:58:58 rgb
486 * Created a sockaddr_key and key_opt socket extension structures.
487 *
488 * Revision 1.5 1999/06/10 05:24:41 rgb
489 * Renamed variables to reduce confusion.
490 *
491 * Revision 1.4 1999/04/29 15:21:11 rgb
492 * Add pfkey support to debugging.
493 * Add return values to init and cleanup functions.
494 *
495 * Revision 1.3 1999/04/15 17:58:07 rgb
496 * Add RCSID labels.
497 *
498 */